110001010010001000001001000111

Borebase ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed by Borebase.

This Privacy Policy applies to our website, and its associated subdomains (collectively, our "Service") alongside our application, Borebase. By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.

1. Introduction and Scope

SIA Borebase is the controller of the personal data described in this policy. Our registered address is Kurzemes prospekts 126-22, Riga, LV-1069, Latvia, and you can reach us at hello@borebase.io.

This policy covers the borebase.io website and its subdomains, the Borebase application, and the emails we send you. It sets out what personal data we process, on what basis we are allowed to process it, who else receives it, how long we keep it, and what you can ask us to do.

It is written to meet Article 13 of the General Data Protection Regulation (EU) 2016/679, which applies to us as a company registered in Latvia.

One distinction runs through the whole document. For your own account data - your name, your email address, your subscription - Borebase is the controller and this policy applies to it. For the content your organisation puts into its projects, including the names of drillers, operators and site contacts recorded on boreholes and soundings, your organisation is the controller and Borebase is its processor: we hold that data on its instructions. If you have been named in someone else's Borebase project, address your request to that organisation and we will help it answer you.

2. Data We Collect

We process the following categories of personal data, and nothing that is not listed here.

  • Account data: your email address, your password (stored only as an Argon2id hash, never in a form anyone can read), your full name, your job title, your organisation name, your preferred language and units, and the dates your account was created and last changed.
  • Membership data: which company account you belong to, your role in it, whether your membership is approved or still pending, and who approved it.
  • Registration data: while you are confirming your email address we hold that address, your name, your company name and a confirmation code. If confirmation is not completed, the record is deleted automatically.
  • Subscription and billing data: your plan, the number of seats, the billing period, invoice and payment identifiers, amounts and currency. Card numbers never reach us - you enter them on Stripe's payment page and Stripe holds them.
  • Communication data: whether you have opted in to our newsletter and when you last changed that choice, and the content of any support message you send us.
  • Project content: the boreholes, soundings, logs, files and reports your organisation uploads. Some fields - the driller of a borehole, the operator of a test - are personal data about people who are not our customers.
  • Technical data: your IP address, which we use to rate-limit requests and block abuse, and ordinary server logs of the requests our servers answer.
  • Cookies and browser storage: the small set described in our Cookie Policy, including your cookie choice, your language and your signed-in session.

Most of this comes from you directly - when you register, subscribe, invite a colleague, upload data or write to us. Technical data is generated by your browser and our servers as you use the service. If a colleague invites you to a company account, we receive your email address from them.

We do not buy personal data from anyone, we do not process special categories of data such as health, biometric or political data, and we never ask you for identity documents.

An email address, a password, your name and your organisation's name are required to open an account: they are what an account consists of, and without them we cannot create one. Job title, preferred language and units are optional and can be left empty. Subscribing additionally requires the billing details Stripe asks for; without them we cannot take payment, and the account stays on its trial until the trial ends.

3. How We Use Your Data

Each purpose below names the legal basis that permits it, as Article 13(1)(c) requires.

  • Creating and running your account, giving you access to your organisation's projects, and letting you import, analyse, visualise and export data. Basis: performance of our contract with you, Article 6(1)(b).
  • Sending the service messages that come with holding an account: email confirmation, password resets, invitations, and notices about your subscription. Basis: performance of our contract, Article 6(1)(b).
  • Taking payment, managing your subscription and seats, and issuing invoices. Basis: performance of our contract, Article 6(1)(b); keeping the resulting accounting records is a legal obligation, Article 6(1)(c).
  • Keeping the service secure and available: rate-limiting requests, blocking abuse, investigating errors, and alerting our own team when something breaks. Basis: our legitimate interest in a service that stays up and is not abused, Article 6(1)(f).
  • Answering your support requests and acting on your feedback. Basis: performance of our contract, Article 6(1)(b), or our legitimate interest in answering people who write to us, Article 6(1)(f).
  • Sending the newsletter and product announcements that are marketing rather than service messages, and setting cookies that are not strictly necessary. Basis: your consent, Article 6(1)(a), which you can withdraw at any time.
  • Meeting obligations the law places on us, and answering lawful requests from authorities. Basis: legal obligation, Article 6(1)(c).

We take no automated decisions that produce legal effects for you or similarly significantly affect you, and we do not profile you. Nothing you do in Borebase feeds an advertising system.

4. Data Sharing and Third Parties

We do not sell, rent or trade personal data, and we use no advertising networks. Personal data leaves us only to the service providers we need in order to run Borebase, and each of them receives only what its part of the service requires.

  • Stripe - payments and subscriptions. Receives your name, your email address and the payment details you enter on its checkout page, and returns to us the identifiers and amounts we need for your invoices.
  • Mapbox - maps. Your browser loads map tiles from Mapbox when you open a project map, which discloses your IP address to Mapbox. Our servers also request static map images from Mapbox for exported PDF reports; those requests carry coordinates, not your identity.
  • Our email provider - delivery of mail over SMTP. Receives the recipient address and the content of the message.
  • Hetzner - server hosting. Operates the servers on which the database and uploaded files are stored.
  • Telegram - internal operational alerts. Short messages about system events, such as a new registration or a failed export, are delivered to a private Borebase channel, and depending on how alerting is configured they can include the email address of the account an event concerns.

Beyond these, we disclose personal data only where the law requires it, or where it is necessary to establish, exercise or defend a legal claim. If Borebase were ever sold or merged, customer data would move with the business, and we would tell you before that happened.

5. Data Security

Passwords are stored only as Argon2id hashes with the parameters OWASP currently recommends. Nobody at Borebase can read your password, and we can never send it back to you - a reset is the only route.

Traffic between your browser and our servers is encrypted in transit with TLS. Sessions use short-lived signed tokens, and changing your password invalidates every token issued before the change.

Every request for data is checked against the company account you belong to, so one organisation cannot read another's projects, and a link to a record you are not entitled to see answers the same way whether or not that record exists.

No system is perfectly secure; if a breach ever puts your rights and freedoms at risk we will notify the supervisory authority within 72 hours and, where the regulation requires it, you as well.

You can help: use a password you use nowhere else, and write to hello@borebase.io as soon as you suspect an account has been compromised.

6. Your Rights

The regulation gives you the following rights over your personal data. Exercising them is free, and we answer within one month of receiving the request.

  • Access, Article 15: a copy of the personal data we hold about you, together with why we hold it, who receives it and how long we keep it.
  • Rectification, Article 16: correction of anything inaccurate and completion of anything incomplete. Most account fields you can change yourself in your profile settings.
  • Erasure, Article 17: deletion of your personal data where we no longer have a reason to hold it. Records we are obliged to keep for accounting, or that we need to defend a legal claim, are the exception, and we will tell you when that applies.
  • Restriction, Article 18: we keep the data but stop using it - for example while you dispute that it is accurate.
  • Portability, Article 20: the data you gave us, in a structured, commonly used and machine-readable format, or transmitted directly to another provider where that is technically feasible.
  • Objection, Article 21: you can object to any processing we base on legitimate interest. If you object to direct marketing we stop at once and do not ask why.

To exercise any of them, write to hello@borebase.io from the address on your account, or tell us clearly which account you mean. We may ask you to confirm who you are before we act, because acting on the wrong person's request would itself be a breach.

Two of these are now buttons, in your account settings: Download my data hands you a copy of your account information, and Delete my account erases it. Everything else is handled by a person, within the one month Article 12(3) allows; if a request is unusually complex we may extend that by up to two further months, and we will tell you why within the first month.

If you believe we have handled your personal data badly, tell us first and we will try to put it right. You also have the right to lodge a complaint with the Latvian supervisory authority, Datu valsts inspekcija (the Data State Inspectorate), or with the authority of the EU country where you live or work: www.dvi.gov.lv

Where we rely on your consent - the newsletter, and cookies that are not strictly necessary - you may withdraw it at any time: use the unsubscribe link in any newsletter, switch the newsletter off in your profile settings, or change your cookie choice on our website. Withdrawing consent stops that processing from the moment you withdraw it; it does not make what we did beforehand unlawful.

7. Data Retention

We keep personal data only for as long as the purpose it was collected for lasts.

  • Account, membership and project data: for as long as the account exists. When your organisation closes its account, or you ask us to close yours, we delete or anonymise your personal data.
  • Unconfirmed registrations: deleted automatically 15 minutes after they are started, and removed from our database the next time anyone registers.
  • Password reset links: valid for one hour, and unusable afterwards.
  • Invitations to join a company account: valid for seven days.
  • Newsletter subscription: kept until you unsubscribe. We keep the fact that you unsubscribed, and the date, so that we do not mail you again by mistake.
  • Payment and invoice records: for as long as Latvian accounting and tax law requires us to keep them, which is longer than the account itself.
  • Server logs and security records: only for as long as they are useful for troubleshooting and for investigating abuse.

If you need the exact period that applies to a particular category, ask us at hello@borebase.io and we will tell you.

8. International Data Transfers

Your account and project data are held by our hosting provider, on servers rented for Borebase. Some of the service providers listed in section 4 are outside the European Economic Area, and using them means personal data reaches those countries.

Stripe and Mapbox are United States companies, or transfer data to the United States. Those transfers are made on the safeguards set out in each provider's own data processing terms - the standard contractual clauses approved by the European Commission and, where the provider is certified under it, the EU-US Data Privacy Framework.

Our internal operational alerts are delivered through Telegram, whose operator Telegram FZ-LLC is established in the United Arab Emirates. Depending on how alerting is configured, an alert can contain the email address of the account it concerns. The United Arab Emirates is not covered by an adequacy decision of the European Commission.

Write to hello@borebase.io if you want to know which safeguard applies to a particular recipient, or to receive a copy of it.

9. Children's Privacy

Borebase is a professional tool sold to companies, consultancies and academic institutions. It is not designed for children, not marketed to them, and we do not knowingly collect personal data from anyone under 16.

If you believe that a child's personal data has reached us - through a registration, or by being recorded in a project - write to hello@borebase.io and we will delete it.

10. Contact Information

SIA Borebase, Kurzemes prospekts 126-22, Riga, LV-1069, Latvia.

Email: hello@borebase.io. Every request under section 6, every question about this policy and any report of a suspected security problem goes to that address.

We may change this policy as the service changes. When we do, the date at the top of this page changes with it, and where a change materially affects you we will say so on our website.

Definitions and key terms

To help explain things as clearly as possible in this Privacy Policy, every time any of these terms are referenced, are strictly defined as:

  • Cookie: small amount of data generated by a website and saved by your web browser.
  • Company: refers to SIA Borebase, Kurzemes prospekts 126-22, Riga, Latvija, LV-1069.
  • Country: Latvia.
  • Customer: the company, organization or person that signs up to use the Borebase Service.
  • Device: any internet connected device such as a phone, tablet, computer.
  • IP address: Every device connected to the Internet is assigned a number known as an Internet protocol (IP) address.
  • Personnel: those individuals who are employed by Borebase or are under contract.
  • Personal Data: any information that directly, indirectly, or in connection with other information allows for identification.
  • Service: the service provided by Borebase as described in the relative terms.
  • Third-party service: a provider that processes data on our behalf so that Borebase can work - payments, maps, email delivery, hosting and internal alerts. Section 4 names them. We use no advertisers and no marketing partners.
  • Website: borebase.io
  • You: a person or entity that is registered with Borebase to use the Services.

Cookie Consent

We use essential cookies for authentication and security. We do not use analytics or advertising cookies; if that ever changes, we will ask for your consent first. Learn more